CVE-2026-76460
Act now ● On CISA KEV — actively exploited
Actively exploited — on the CISA KEV list.
CVSS base
—
EPSS — probability of exploitation (30 days)
0.8%
54.5th percentile
CISA KEV
Listed
Added 2026-09-16 · patch by 2026-09-19
Weakness / dates
—
Published — · modified —
Description
Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.